LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0130: Ajax Security Team

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.[1]

EnterpriseG0130GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Ajax Security Team matters because ATT&CK links the group to a shift from website defacement toward malware-based cyber espionage, with reported targeting of the US defense industrial base and Iranian users of anti-censorship technologies. For leaders, the practical issue is not the name of the actor alone, but whether the organization can withstand phishing-led access, credential theft from users and browsers, keylogging, tool transfer, and exploitation of SQL injection tooling associated through ATT&CK relationships.

Executive priority

Prioritize this as a validation case for phishing resilience, identity protection, endpoint visibility, web application security, and incident response readiness. The object has no official ATT&CK detection guidance and no group-level platform or tactic fields, so executives should ask whether existing controls produce evidence across the related behaviors: spearphishing attachments or services, malicious file execution, credential collection, ingress tool transfer, and SQL injection tool activity. This is especially relevant where defense industrial base exposure, sensitive user populations, or externally facing web applications are business-critical.

Technical view

SOC and IR teams should use the ATT&CK relationships as the defensive map: T1566.001 and T1566.003 for initial-access phishing paths, T1204.002 for user-driven malicious file execution, T1056.001 and T1555.003 for credential collection, T1105 for inbound tool transfer, and S0224/S0225 for SQL injection tooling context. Because the group object itself provides no official detection text, coverage should be proven through local telemetry, alert logic, and incident playbooks rather than assumed from actor naming. Validate whether detections connect email or service-delivered lures to endpoint execution, credential access attempts, and subsequent file/tool transfers.

Likely telemetry

  • Email security logs for attachments, sender metadata, delivery disposition, and user interaction where available
  • Third-party messaging or collaboration service audit logs relevant to spearphishing via service
  • Endpoint process, file creation, script execution, and child-process telemetry for malicious file execution
  • Browser credential store access indicators and endpoint file access telemetry where collected
  • Keystroke-capture or suspicious input-monitoring indicators from endpoint security tools

Detection direction

  • Do not rely on actor-name detections; build behavior-based coverage around the related ATT&CK techniques and software.
  • Tune phishing detections for both enterprise email and third-party services, since ATT&CK lists spearphishing attachment and spearphishing via service relationships.
  • Correlate user-opened files with endpoint execution and follow-on credential access or network transfer activity to reduce isolated false positives.
  • Validate visibility into browser credential access and keylogging-like behavior, which may be noisy or dependent on endpoint sensor depth.
  • Review web application monitoring for SQL injection tooling such as Havij and sqlmap, while accounting for legitimate penetration testing activity as a false-positive source.

Mitigation priorities

  • Strengthen phishing controls and user reporting workflows for attachments and messages delivered through third-party services.
  • Harden endpoint execution policy and attachment handling to reduce user-driven malicious file execution risk.
  • Protect credentials with least privilege, multi-factor authentication where applicable, and controls that reduce stored browser credential exposure.
  • Ensure endpoint monitoring and response processes can investigate suspected keylogging or credential theft behavior.
  • Control and monitor inbound file/tool transfer paths through proxy, firewall, EDR, and network logging.
Additional notes and limits

ATT&CK describes Ajax Security Team as active since at least 2010 and believed to operate out of Iran, with a reported transition by 2014 from defacement to malware-based espionage campaigns. Relationships supplied for this object include Havij, sqlmap, keylogging, ingress tool transfer, malicious file execution, browser credential theft, and spearphishing via attachment or service. Several aliases and campaign names are listed, but the external references also indicate ambiguity or potential relationships among naming clusters, so reporting should preserve source context.

The group object provides no official detection text, no group-level platforms, and no group-level tactics. The guidance above is derived only from supplied ATT&CK description, external references, and relationships; it does not establish current activity, customer exposure, attribution certainty, or detection coverage in any environment. Local telemetry, business exposure, and authorized testing records are required to determine relevance and priority.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Ajax Security Team

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

6 rows
DomainIDNameRelationship / procedure
EnterpriseT1056.001KeyloggingSub-technique

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.[2]

EnterpriseT1566.003Spearphishing via ServiceSub-technique

Ajax Security Team has used various social media channels to spearphish victims.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Ajax Security Team has used personalized spearphishing attachments.[2]

EnterpriseT1204.002Malicious FileSub-technique

Ajax Security Team has lured victims into executing malicious files.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.[2]

EnterpriseT1105Ingress Tool Transfer

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0225: sqlmap

sqlmap is an open source penetration testing tool that can be used to automate the process of detecting and exploiting SQL injection flaws. [1]

ToolEnterprise

S0224: Havij

Havij is an automatic SQL Injection tool distributed by the Iranian ITSecTeam security company. Havij has been used by penetration testers and adversaries. [1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
33e1685a737a7bd4...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle33e1685a737a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  2. [2]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  3. [3]
    AjaxTM

    (Citation: FireEye Operation Saffron Rose 2013)

  4. [4]
    AjaxTM

    (Citation: FireEye Operation Saffron Rose 2013)

  5. [5]
    AjaxTM

    (Citation: FireEye Operation Saffron Rose 2013)

  6. [6]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  7. [7]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  8. [8]
    CrowdStrike Flying Kitten

    Dahl, M.. (2014, May 13). Cat Scratch Fever: CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN. Retrieved May 27, 2020.

    Open source URL
  9. [9]
    CrowdStrike Flying Kitten

    Dahl, M.. (2014, May 13). Cat Scratch Fever: CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN. Retrieved May 27, 2020.

    Open source URL
  10. [10]
    CrowdStrike Flying Kitten

    Dahl, M.. (2014, May 13). Cat Scratch Fever: CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN. Retrieved May 27, 2020.

    Open source URL
  11. [11]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  12. [12]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  13. [13]
    Flying Kitten

    (Citation: CrowdStrike Flying Kitten )

  14. [14]
    Flying Kitten

    (Citation: CrowdStrike Flying Kitten )

  15. [15]
    Flying Kitten

    (Citation: CrowdStrike Flying Kitten )

  16. [16]
    IranThreats Kittens Dec 2017

    Iran Threats . (2017, December 5). Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code. Retrieved May 28, 2020.

    Open source URL
  17. [17]
    IranThreats Kittens Dec 2017

    Iran Threats . (2017, December 5). Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code. Retrieved May 28, 2020.

    Open source URL
  18. [18]
    IranThreats Kittens Dec 2017

    Iran Threats . (2017, December 5). Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code. Retrieved May 28, 2020.

    Open source URL
  19. [19]
    Operation Saffron Rose

    (Citation: FireEye Operation Saffron Rose 2013)

  20. [20]
    Operation Saffron Rose

    (Citation: FireEye Operation Saffron Rose 2013)

  21. [21]
    Operation Saffron Rose

    (Citation: FireEye Operation Saffron Rose 2013)

  22. [22]
    Operation Woolen-Goldfish

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and the campaign Operation Woolen-Goldfish.(Citation: Check Point Rocket Kitten)(Citation: TrendMicro Operation Woolen Goldfish March 2015)

  23. [23]
    Operation Woolen-Goldfish

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and the campaign Operation Woolen-Goldfish.(Citation: Check Point Rocket Kitten)(Citation: TrendMicro Operation Woolen Goldfish March 2015)

  24. [24]
    Operation Woolen-Goldfish

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and the campaign Operation Woolen-Goldfish.(Citation: Check Point Rocket Kitten)(Citation: TrendMicro Operation Woolen Goldfish March 2015)

  25. [25]
    Rocket Kitten

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and Rocket Kitten.(Citation: Check Point Rocket Kitten)(Citation: IranThreats Kittens Dec 2017)

  26. [26]
    Rocket Kitten

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and Rocket Kitten.(Citation: Check Point Rocket Kitten)(Citation: IranThreats Kittens Dec 2017)

  27. [27]
    Rocket Kitten

    Analysis of infrastructure, tools, and modes of operation revealed a potential relationship between [Ajax Security Team](https://attack.mitre.org/groups/G0130) and Rocket Kitten.(Citation: Check Point Rocket Kitten)(Citation: IranThreats Kittens Dec 2017)

  28. [28]
    TrendMicro Operation Woolen Goldfish March 2015

    Cedric Pernet, Kenney Lu. (2015, March 19). Operation Woolen-Goldfish - When Kittens Go phishing. Retrieved April 21, 2021.

    Open source URL
  29. [29]
    TrendMicro Operation Woolen Goldfish March 2015

    Cedric Pernet, Kenney Lu. (2015, March 19). Operation Woolen-Goldfish - When Kittens Go phishing. Retrieved April 21, 2021.

    Open source URL
  30. [30]
    TrendMicro Operation Woolen Goldfish March 2015

    Cedric Pernet, Kenney Lu. (2015, March 19). Operation Woolen-Goldfish - When Kittens Go phishing. Retrieved April 21, 2021.

    Open source URL
  31. [31]
    mitre-attackG0130
    Open source URL
  32. [32]
    mitre-attackG0130
    Open source URL
  33. [33]
    mitre-attackG0130
    Open source URL
  34. [34]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  35. [35]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  36. [36]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  37. [37]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  38. [38]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  39. [39]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  40. [40]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  41. [41]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  42. [42]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  43. [43]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  44. [44]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  45. [45]
    FireEye Operation Saffron Rose 2013

    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

    Open source URL
  46. [46]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  47. [47]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
  48. [48]
    Check Point Rocket Kitten

    Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.